40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-23741
Software Genérico General
9.8
CRITICAL
EPSS
24.2%
2024 2 PoCs

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-36389
DeviceHub General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-330 1 PoC

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

CVE-2021-27664
exacqVision Web Service General
9.8
CRITICAL
EPSS
0.3%
2021 CWE-269 1 PoC

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

CVE-2004-2154
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2004 2 PoCs

CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive.

CVE-2017-2894
Mongoose General
9.8
CRITICAL
EPSS
5.1%
2017 1 PoC

An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

CVE-2024-8381
Firefox General
9.8
CRITICAL
EPSS
11.6%
2024 1 PoC

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVE-2023-32653
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-191 1 PoC

An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2024-34943
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

CVE-2023-49236
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.

CVE-2021-23377
onion-oled-js General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-40507
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in execution.

CVE-2024-38396
Software Genérico General
9.8
CRITICAL
EPSS
10.3%
2024 3 PoCs

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

CVE-2025-2747
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.

CVE-2024-54804
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

CVE-2023-20520
1st Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

CVE-2023-1698
Compact Controller CC100 General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2023 CWE-78 6 PoCs

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVE-2025-24204
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVE-2025-43027
Genetec Security Center General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-284 1 PoC

A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative access to the Genetec Security Center system. The Genetec engineering team discovered this issue internally. There is currently no evidence that this vulnerability has been exploited in the wild.

CVE-2025-30452
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validation issue was addressed.

CVE-2025-54490
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 9090 of biosig.c on the current master branch (35a819fa), when the Tag is 64: else if (tag==64) //0x40 { // preamble char tmp[256]; // [1] curPos += ifread(tmp,1,len,h